CVE-2015-5295
published 2016-01-20CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users…
PriorityP426medium5.4CVSS 3.0
AVNACLPRLUINSUCLINAL
EPSS
2.93%
85.5th percentile
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | heat | < heat 1:6.0.0~rc3-1 (bookworm) | heat 1:6.0.0~rc3-1 (bookworm) |
| fedoraproject | fedora | — | — |
| openstack | heat | >= 0 < 1:6.0.0~rc3-1 | 1:6.0.0~rc3-1 |
| openstack | heat | >= 0 < 1:6.0.0~rc3-1 | 1:6.0.0~rc3-1 |
| openstack | heat | >= 0 < 1:6.0.0~rc3-1 | 1:6.0.0~rc3-1 |
| openstack | heat | >= 0 < 1:6.0.0~rc3-1 | 1:6.0.0~rc3-1 |
| openstack | orchestration_api | >= 2015.1.0 < 2015.1.3 | 2015.1.3 |
| openstack | orchestration_api | >= 5.0.0 < 5.0.1 | 5.0.1 |
| oracle | solaris | — | — |
| redhat | openstack | — | — |
CVSS provenance
nvdv3.05.4MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:L
nvdv2.05.5MEDIUMAV:N/AC:L/Au:S/C:P/I:N/A:P
osv5.4MEDIUM
vendor_debian5.4MEDIUM
vendor_redhat5.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2w55-prvj-mgc2: The template-validate command in OpenStack Orchestration API (Heat) before 2015
ghsa_unreviewed·2022-05-14
CVE-2015-5295 [MEDIUM] CWE-119 GHSA-2w55-prvj-mgc2: The template-validate command in OpenStack Orchestration API (Heat) before 2015
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
OSV
CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015
osv·2016-01-20·CVSS 5.4
CVE-2015-5295 [MEDIUM] CVE-2015-5295: The template-validate command in OpenStack Orchestration API (Heat) before 2015
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
Red Hat
openstack-heat: Vulnerability in Heat template validation leading to DoS
vendor_redhat·2016-01-19·CVSS 5.4
CVE-2015-5295 [MEDIUM] CWE-400 openstack-heat: Vulnerability in Heat template validation leading to DoS
openstack-heat: Vulnerability in Heat template validation leading to DoS
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
A vulnerability was discovered in the OpenStack Orchestration service (heat), where a specially formatted template could be used to trick the heat-engine service into opening a local file. Although the file contents are never disclosed to the end user, an OpenStack-authenticated attacker could use this flaw to cause a denial of service or determine whether a given file name is present on the server
Debian
CVE-2015-5295: heat - The template-validate command in OpenStack Orchestration API (Heat) before 2015....
vendor_debian·2015·CVSS 5.4
CVE-2015-5295 [MEDIUM] CVE-2015-5295: heat - The template-validate command in OpenStack Orchestration API (Heat) before 2015....
The template-validate command in OpenStack Orchestration API (Heat) before 2015.1.3 (kilo) and 5.0.x before 5.0.1 (liberty) allows remote authenticated users to cause a denial of service (memory consumption) or determine the existence of local files via the resource type in a template, as demonstrated by file:///dev/zero.
Scope: local
bookworm: resolved (fixed in 1:6.0.0~rc3-1)
bullseye: resolved (fixed in 1:6.0.0~rc3-1)
forky: resolved (fixed in 1:6.0.0~rc3-1)
sid: resolved (fixed in 1:6.0.0~rc3-1)
trixie: resolved (fixed in 1:6.0.0~rc3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-5295 openstack-heat: Vulnerability in Heat template validation leading to DoS [fedora-all]
bugzilla·2016-01-19·CVSS 5.4
CVE-2015-5295 [MEDIUM] CVE-2015-5295 openstack-heat: Vulnerability in Heat template validation leading to DoS [fedora-all]
CVE-2015-5295 openstack-heat: Vulnerability in Heat template validation leading to DoS [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple
Bugzilla
CVE-2015-5295 openstack-heat: Vulnerability in Heat template validation leading to DoS
bugzilla·2016-01-13·CVSS 5.4
CVE-2015-5295 [MEDIUM] CVE-2015-5295 openstack-heat: Vulnerability in Heat template validation leading to DoS
CVE-2015-5295 openstack-heat: Vulnerability in Heat template validation leading to DoS
A vulnerability in Heat template validation was reported. By referencing a local file like /dev/zero, an authenticated user may trick the heat engine service to load arbitrary local file content resulting in a Denial of Service attack through memory exhaustion. Note that the file content is not written back to the user, though the user can determine if a file exists and if it is readable by heat-engine.
Affects versions <=2015.1.2, ==5.0.0. All Heat setups are affected.
Discussion:
Created attachment 1114470
Master/mitaka patch
---
Created attachment 1114471
Stable/kilo patch
---
Created attachment 1114472
Stable/liberty patch
---
Created attachment 1114967
stable/juno patch
---
Created attac
http://lists.fedoraproject.org/pipermail/package-announce/2016-February/176700.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0266.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/81438https://bugs.launchpad.net/heat/+bug/1496277https://security.openstack.org/ossa/OSSA-2016-003.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2016-February/176700.htmlhttp://rhn.redhat.com/errata/RHSA-2016-0266.htmlhttp://www.oracle.com/technetwork/topics/security/bulletinapr2016-2952098.htmlhttp://www.securityfocus.com/bid/81438https://bugs.launchpad.net/heat/+bug/1496277https://security.openstack.org/ossa/OSSA-2016-003.html
2016-01-20
Published